CVE Database /
CVE-2024-37497
CVE · High
CVE-2024-37497 — JetThemeCore [jet-theme-core] < 2.2.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-37497
|
JetThemeCore [jet-theme-core] < 2.2.1 |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
7.7
|
< 2.2.1
|
2.2.1 |
2024-07-04 |
—
|
CVE-2024-37497
The JetThemeCore for Elementor plugin versions through 2.2.0 contains a flaw where file path validation is inadequate, allowing authenticated users with subscriber privileges or higher to remove arbitrary files from the server. This vulnerability can be exploited to delete critical files like wp-config.php, potentially enabling attackers to achieve remote code execution.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings